First published: Mon Jan 14 2019(Updated: )
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=2.4.3 | ||
>=3.0.0<=3.0.4 | ||
>=8.0.6<=8.1.0 | ||
=12.0.0 | ||
=12.1.0 | ||
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6<=8.1.0 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3773 is a vulnerability in Spring Web Services that allows for XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Versions 2.4.3, 3.0.4, and older unsupported versions of Spring Web Services are affected by CVE-2019-3773.
The severity of CVE-2019-3773 is critical, with a severity value of 9.8.
To fix CVE-2019-3773, it is recommended to update to a supported version of Spring Web Services.
You can find more information about CVE-2019-3773 at the following references: [link1], [link2], [link3].